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What is Personally 
Identifiable Information? 


The Cisco Data Protection and Privacy Policy \ 
defines PII as any information or collection of 
data that enables identification of an individual. \ 


In Europe, the General Data Protection Regulation 
(GDPR) refers to PII as Personal Data. The Cisco Online 
Privacy Statement calls it personal information. None 

of these definitions or terms are wrong; they all express 


the same notion and underlying concept. 
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What makes information 
or data “personal”? 


In practical terms, personal information or personal 
data is “personal” when it contains personally 
identifiable information by itself or in a collection. 


Cisco privacy policies 
address the following data: 


Í Data that directly identifies an individual like an individual’s name, 
address, phone number, or tax identification number. 


A collection of data that together identifies an individual because 
2 no one else has those characteristics, for example, anonymous 
information that, when combined, can only be a single person. 


Data that is associated with personal identifiers like unique device 

> and network identifiers such as the universally unique identifier 
(UUID) and IP addresses, or other forms of telemetry or machine data 

that can be linked to an individual’s device or endpoint. 


What is sensitive PII? 


Some PII is classified sensitive either culturally, under the law, or both. Sensitive PII 
(i.e. sensitive data) is PII that can be used to embarrass, harm, or discriminate against 
someone or can be used for identity theft or fraud to the data subject. 


If PII is sufficiently removed or deidentified so the data can not link to an individual 
person, it can become just “information” as long as it can’t be reidentified. 
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Specific examples of PII 


Cisco Technical Assistance 
Center (TAC) case files 


If an attachment to a support case 
that contains a customer’s email address 
with contact details 


An employee’s 
grade level 


Logon addresses 


If for an end user’s (i.e., 


If for a specific employee an individual’s) email address 


If not for a specific If for a domain URL 
employee 
If an attachment to a support 


case contains network configuration files 


GEO location 
If data is the GPS of an end user 


A street address IP addresses 


If for an individual If for an end user’s 


Piao busines (i.e., an individual’s) device 


If for a system in a rack 
at a data center 


(i.e., an individual) 


If data is derived from an IP 
address (i.e., at a large geographical 


area that is not specific to an individual) 


Determining if data is PII 


Put yourself in the individual’s place and ask yourself, “Can the data 
(or aggregate of data) be used to identify or contact an individual?” 
“Can it be linked to an individual’s device like their laptop or smartphone?” 


The data is not PII 
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For more detailed information r 
about Cisco’s perspective on PII, 
visit 
Afeafe, 


CISCO. 
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